Description
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in PoolCustomerController.get use bare pool-read permission checks without the CsPermission resourceId binding that enforces per-record data scope. An authenticated user with the ordinary CLUE_MANAGEMENT_POOL:READ or CUSTOMER_MANAGEMENT_POOL:READ permission can supply another record's id and cause unscoped primary-key getters to return leads or accounts owned by other users, departments, or organizations. Exposed data includes contact names, phone numbers, owner and department attribution, and custom field values. This issue is fixed in version 1.7.4.
Published: 2026-09-18
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of lead and account data
Action: Patch
AI Analysis

Impact

A flaw in CordysCRM’s lead and account retrieval endpoints allows an authenticated user to read records for any lead or account by supplying id check means that standard read permissions grant access to records outside the intended scope. An attacker could obtain contact names, phone numbers, owner, department information, and custom field values for users, departments, or organizations they are not authorized to view.

Affected Systems

CordysCRM 1.7.3 and earlier, released by 1Panel-dev, are affected. The issue was resolved in version 1.7.4, released by 1Panel-dev. Any deployment of the open source CRM prior to this release is vulnerable.

Risk and Exploitability

The vulnerability is scored at CVSS 5.8, indicating moderate severity. Exploitability is not quantified by EPSS or KEV inclusion, but the flaw is straightforward to abuse once an authenticated user gains the CLUE_MANAGEMENT_POOL:READ or CUSTOMER_MANAGEMENT_POOL:READ rights. The likely vector is an authenticated session or API consumer acting with requires only valid credentials and the ability to supply an alternative primary key, it can be performed by any user with the ordinary read permission, making the risk significant for environments with broad read privileges.

Generated by OpenCVE AI on September 19, 2026 at 11:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CordysCRM to version 1.7.4 or later, which removes the deficient permission check.
  • If upgrading immediately is not possible, restrict users to the minimal read permissions required for their role, or disable the /pool/lead/get and /pool/account/get endpoints for unauthenticated or low‑privilege users.
  • Apply a temporary whitelisting rule to enforce CsPermission resourceId bindings on the affected endpoints until the patch is deployed.

Generated by OpenCVE AI on September 19, 2026 at 11:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared 1panel-dev
1panel-dev cordyscrm
Vendors & Products 1panel-dev
1panel-dev cordyscrm

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in PoolCustomerController.get use bare pool-read permission checks without the CsPermission resourceId binding that enforces per-record data scope. An authenticated user with the ordinary CLUE_MANAGEMENT_POOL:READ or CUSTOMER_MANAGEMENT_POOL:READ permission can supply another record's id and cause unscoped primary-key getters to return leads or accounts owned by other users, departments, or organizations. Exposed data includes contact names, phone numbers, owner and department attribution, and custom field values. This issue is fixed in version 1.7.4.
Title CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and accounts
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

1panel-dev Cordyscrm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:48:10.915Z

Reserved: 2026-08-19T22:43:14.890Z

Link: CVE-2026-76901

cve-icon Vulnrichment

Updated: 2026-09-21T19:40:09.435Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:21.970

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-76901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:15:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key